We are seeking a highly skilled and motivated Bootloader Engineer with strong expertise in ARM64 platform bring-up and secure bootloader development for SONiC-based networking operating systems on the ARMv8 or ARMv9 SoC. In this role, you will design, develop, and optimize bootloaders (U-Boot or UEFI) and trusted firmware components, enabling secure and efficient system initialization, firmware chain-of-trust, and FIT or other combined image deployment on high-performance ARM platforms. You will collaborate closely with hardware / FPGA, Linux Kernel, and SONiC software teams to integrate secure and non-secure boot flows, set up secure signing server infrastructure and signing workflows, enable TPM/eHSM-based measurable boot, and ensure platform integrity through attestation and reliable recovery mechanisms. This position requires strong knowledge of ARM64 architecture, boot flow, memory initialization, storage management and low-level board firmware development for hyperscale data center environments.
Key Responsibilities
- :Design, develop, and optimize U-Boot bootloaders and trusted firmware for ARM64 platforms
- .Implement secure and non-secure boot flows integrating with TPM/eHSM for measured boot and attestation
- .Set up and maintain secure signing server infrastructure and signing workflows for secure boot, including key provisioning, certificate management, access control, audit logging, and integration with firmware release pipelines
- .Develop and maintain FIT image (Flattened Image Tree) for SONiC firmware packaging and boot chain management
- .Work with hardware and software teams to ensure reliable bootloader-to-kernel transitions, memory initialization (DDR tuning), and peripheral bring-up
- .Contribute to secure firmware digital signing, verification, rollback and update pipelines
- .Validate platform boot performance /time, reliability, and compliance with secure manufacturing workflows
- .Document design, test procedures, and bring-up results for internal and customer release milestones
.
Required Skills & Qualificatio
- ns:Bachelor’s or master’s degree in computer engineering, electrical engineering, or related fie
- ld.Solid experience in C and C++ programming for low-level firmware and boot-loader developme
- nt.Deep understanding of ARM64 architecture, exception levels, and TrustZone-based secure world desi
- gn.Experience working on bootloader, reflashing, software update, and recovery flows for ARM64-based server syste
- ms.Hands-on experience with U-Boot, Trusted Firmware-A, and FIT image creation and validati
- on.Strong familiarity with eMMC, SPI NOR/NAND, NVMe and USB storage interfac
- es.Understanding of secure boot, secure signing server setup, key provisioning, and signature verification mechanis
- ms.Ability to debug across hardware/software boundaries using JTAG, serial console, and low-level logging too
- ls.Self-driven, highly collaborative, and detail-oriented individual passionate about secure, scalable ARM platfor
ms.
Preferred Qualificati
- ons:Familiarity with TPM-based attestation, key ladder architectures, and measured boot fl
- ows.Knowledge of Linux kernel bring-up, device tree overlays, and early initialization framewo
- rks.Experience with CI/CD pipelines for firmware and bootloader validat
ion.
Why Joi
- n Us?Work on next-generation ARM64 platforms powering SONiC-based hyperscale data cen
- ters.Build and optimize secure boot and trusted firmware at the core of SONiC and OCS infrastruc
- ture.Collaborate with world-class teams across hardware, Linux Kernel, and networking operating system dom
- ains.Contribute to shaping the future of secure, high-performance disaggregated networ
king.